CVE-2026-42349General(clerk / clerk\/astro)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Clerk JavaScript is the official JavaScript repository for Clerk authentication. has(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other framework SDKs can return true for certain combined authorization checks when the result should be false, allowing a gated action to proceed for a user who does not satisfy the full set of requested conditions. This call shape can be bypassed if certain conditions are met: a has() or auth.protect() call that combines a reverification check with any of role, permission, feature, or plan, or that combines a billing check (feature or plan) with a role or permission check. This vulnerability is fixed in @clerk/clerk-js 5.125.10 and 6.7.5.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-754CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • clerk\/astro
  • clerk\/backend
  • clerk\/chrome-extension
  • clerk\/clerk-expo

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
clerk\/astroclerk\/backendclerk\/chrome-extensionclerk\/clerk-expoclerk\/clerk-jsclerk\/clerk-reactclerk\/expoclerk\/expressclerk\/fastifyclerk\/hono

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-11: 105-11
Signal classification1 categories
General
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CVE@CVEnew
    General

    CVE-2026-42349 Clerk JavaScript is the official JavaScript repository for Clerk authentication. has(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/… https://www.cve.org/CVERecord?id=CVE-2026-42349

    Post summary

    The message merely references CVE-2026-42349 and some Clerk JavaScript functions, without providing exploit code, patch info, or active exploitation evidence.

    00000101
    57.5K followersView on X
CPE platform detail17 entries

17 of 17 entries

PartVendorProductVersionTarget SWTarget HW
Appclerkclerk\/astro-node.js-
Appclerkclerk\/backend-node.js-
Appclerkclerk\/chrome-extension-node.js-
Appclerkclerk\/clerk-expo-node.js-
Appclerkclerk\/clerk-js-node.js-
Appclerkclerk\/clerk-react-node.js-
Appclerkclerk\/expo-node.js-
Appclerkclerk\/express-node.js-
Appclerkclerk\/fastify-node.js-
Appclerkclerk\/hono-node.js-
Appclerkclerk\/nextjs-node.js-
Appclerkclerk\/nuxt-node.js-
Appclerkclerk\/react-node.js-
Appclerkclerk\/react-router-node.js-
Appclerkclerk\/shared-node.js-
Appclerkclerk\/tanstack-react-start-node.js-
Appclerkclerk\/vue-node.js-

Explore more